Mozilla Foundation Security Advisory 2012-35

Privilege escalation through Mozilla Updater and Windows Updater Service

Announced

June 5, 2012

Reporter

James Forshaw

Impact

Critical

Products

Firefox, SeaMonkey, Thunderbird

Fixed in

Firefox 13

SeaMonkey 2.10

Thunderbird 13

Description

Security researcher James Forshaw of Context Information
Security found two issues with the Mozilla updater and the Mozilla updater service introduced in Firefox 12 for Windows. The first issue allows Mozilla's updater to load a local DLL file in a privileged context. The updater
can be called by the Updater Service or independently on systems that do not use
the service. The second of these issues allows for the updater service to load an arbitrary local DLL file, which can then be run with the same system privileges used by the service. Both of these issues require local file system access to be exploitable.